<!DOCTYPE html>


<html lang="en">
  

    <head>
      <meta charset="utf-8" />
        
      <meta
        name="viewport"
        content="width=device-width, initial-scale=1, maximum-scale=1"
      />
      <title>高交互平行蜜罐的基础知识 |  小玉玉的博客</title>
  <meta name="generator" content="hexo-theme-ayer">
      
      <link rel="shortcut icon" href="/favicon.ico" />
       
<link rel="stylesheet" href="/dist/main.css">

      <link
        rel="stylesheet"
        href="https://cdn.jsdelivr.net/gh/Shen-Yu/cdn/css/remixicon.min.css"
      />
      
<link rel="stylesheet" href="/css/custom.css">
 
      <script src="https://cdn.jsdelivr.net/npm/pace-js@1.0.2/pace.min.js"></script>
       
 

      <!-- mermaid -->
      
    </head>
  </html>
</html>


<body>
  <div id="app">
    
      
    <main class="content on">
      <section class="outer">
  <article
  id="post-高交互平行蜜罐的基础知识"
  class="article article-type-post"
  itemscope
  itemprop="blogPost"
  data-scroll-reveal
>
  <div class="article-inner">
    
    <header class="article-header">
       
<h1 class="article-title sea-center" style="border-left:0" itemprop="name">
  高交互平行蜜罐的基础知识
</h1>
 

      
    </header>
     
    <div class="article-meta">
      <a href="/2021/04/08/%E9%AB%98%E4%BA%A4%E4%BA%92%E5%B9%B3%E8%A1%8C%E8%9C%9C%E7%BD%90%E7%9A%84%E5%9F%BA%E7%A1%80%E7%9F%A5%E8%AF%86/" class="article-date">
  <time datetime="2021-04-08T11:58:54.000Z" itemprop="datePublished">2021-04-08</time>
</a>   
<div class="word_count">
    <span class="post-time">
        <span class="post-meta-item-icon">
            <i class="ri-quill-pen-line"></i>
            <span class="post-meta-item-text"> Word count:</span>
            <span class="post-count">1.2k</span>
        </span>
    </span>

    <span class="post-time">
        &nbsp; | &nbsp;
        <span class="post-meta-item-icon">
            <i class="ri-book-open-line"></i>
            <span class="post-meta-item-text"> Reading time≈</span>
            <span class="post-count">3 min</span>
        </span>
    </span>
</div>
 
    </div>
      
    <div class="tocbot"></div>




  
    <div class="article-entry" itemprop="articleBody">
       
  <h1 id="什么是平行高交互蜜罐"><a href="#什么是平行高交互蜜罐" class="headerlink" title="什么是平行高交互蜜罐"></a>什么是平行高交互蜜罐</h1><p>平行高交互蜜罐就是在防守方网络范围中<strong>单独开辟出一整套独立的网络环境</strong>并且在网络环境<strong>外部也有</strong>“客户端”概念上的蜜罐与之交互，并且产生的数据能和真实业务产生一定的<strong>逻辑关系而又不具备敏感性的信息</strong>。蜜罐本身所具有的内容也是和真实业务所平行的内容迭代。</p>
<p>高交互中除了具有传统模拟业务的功能之外，还应该有基于业务逻辑内的<strong>高可获权性和隐藏于逻辑外的额外溯源功能。</strong></p>
<h2 id="平行高交互式蜜罐的基本结构"><a href="#平行高交互式蜜罐的基本结构" class="headerlink" title="平行高交互式蜜罐的基本结构"></a>平行高交互式蜜罐的基本结构</h2><p>我们以传统概念上的网络可信任范围划分：</p>
<h3 id="范围内："><a href="#范围内：" class="headerlink" title="范围内："></a>范围内：</h3><h4 id="服务端的蜜罐"><a href="#服务端的蜜罐" class="headerlink" title="服务端的蜜罐"></a>服务端的蜜罐</h4><p>具有平行模拟真实业务的服务端</p>
<h4 id="独立的服务端数据存储"><a href="#独立的服务端数据存储" class="headerlink" title="独立的服务端数据存储"></a>独立的服务端数据存储</h4><p>用于存储产生的模拟交互和攻击者交互数据</p>
<h4 id="用于溯源的资料存储"><a href="#用于溯源的资料存储" class="headerlink" title="用于溯源的资料存储"></a>用于溯源的资料存储</h4><p>攻击者交互过程中产生的所有信息的独立存储</p>
<h4 id="黑白名单"><a href="#黑白名单" class="headerlink" title="黑白名单"></a>黑白名单</h4><p>用于区分攻击者交互和“客户端”蜜罐交互的黑白名单</p>
<h4 id="溯源的攻击工具（不推荐在服务端直接部署、推荐单独的网络环境）"><a href="#溯源的攻击工具（不推荐在服务端直接部署、推荐单独的网络环境）" class="headerlink" title="溯源的攻击工具（不推荐在服务端直接部署、推荐单独的网络环境）"></a>溯源的攻击工具（不推荐在服务端直接部署、推荐单独的网络环境）</h4><p>用于溯源攻击者的相关工具</p>
<h3 id="范围外："><a href="#范围外：" class="headerlink" title="范围外："></a>范围外：</h3><h4 id="客户端"><a href="#客户端" class="headerlink" title="客户端"></a>客户端</h4><p>用于模拟用户的功能</p>
<h4 id="专用于客户端的信息存储"><a href="#专用于客户端的信息存储" class="headerlink" title="专用于客户端的信息存储"></a>专用于客户端的信息存储</h4><p>用于收集攻击者可能攻击的业务风险而导致的用户数据安全从而进行溯源</p>
<h1 id="高交互平行蜜罐与传统蜜罐的区别"><a href="#高交互平行蜜罐与传统蜜罐的区别" class="headerlink" title="高交互平行蜜罐与传统蜜罐的区别"></a>高交互平行蜜罐与传统蜜罐的区别</h1><p>传统蜜罐特点就是适用性强、布置速度和便捷性相对较好，但是缺点也很明显，交互内容太少并且数据可信度不高，时间节点上也看不出业务的逻辑性，所以很容易被发现。</p>
<p>高交互式的蜜罐特点就是交互内容很多但是市面上现有的蜜罐都还是存在内容数据的可信度低的问题。</p>
<p>平行高交互蜜罐具有完整的和真实业务有逻辑联系但是诱饵数据有脱敏保证的，并且交互内容是镜像与真实业务有完整逻辑闭环的蜜罐，可信度很高，但是缺点就是部署时间很长。</p>
<h1 id="以最小成本为例讲企业如何实际部署"><a href="#以最小成本为例讲企业如何实际部署" class="headerlink" title="以最小成本为例讲企业如何实际部署"></a>以最小成本为例讲企业如何实际部署</h1><p>我们以上文中提到的基本结构为基础。</p>
<h3 id="服务端的蜜罐："><a href="#服务端的蜜罐：" class="headerlink" title="服务端的蜜罐："></a>服务端的蜜罐：</h3><p>微服务，Saas等都是成本低、部署相对较快、可定制内容比较全面的应用</p>
<h3 id="独立的服务端数据存储-1"><a href="#独立的服务端数据存储-1" class="headerlink" title="独立的服务端数据存储"></a>独立的服务端数据存储</h3><p>为了提高可信性，推荐使用与真实业务类似的架构但是规模上可以大幅度缩小的数据存储结构。也就是在交互外的内容只需要做到有就行，交互内的内容只需要做到“看起来足够就行”（可以使用数据填充或者用机器学习模拟数据等方式）。在部署时还要注意的就是时间戳一定要和真实业务有关联。</p>
<h3 id="用户溯源的资料存储"><a href="#用户溯源的资料存储" class="headerlink" title="用户溯源的资料存储"></a>用户溯源的资料存储</h3><p>容量可以很小，结构可以简单，但是安全性和隐蔽性需要有保证必须是高优先级。</p>
<h3 id="黑白名单-1"><a href="#黑白名单-1" class="headerlink" title="黑白名单"></a>黑白名单</h3><p>以规则形式存在即可</p>
<h4 id="溯源的攻击工具"><a href="#溯源的攻击工具" class="headerlink" title="溯源的攻击工具"></a>溯源的攻击工具</h4><p>常用工具</p>
<h4 id="客户端-1"><a href="#客户端-1" class="headerlink" title="客户端"></a>客户端</h4><p>不限形式，能正常使用服务端功能即可，客户端数量越多越好</p>
<h4 id="专用于客户端的信息存储-1"><a href="#专用于客户端的信息存储-1" class="headerlink" title="专用于客户端的信息存储"></a>专用于客户端的信息存储</h4><p>越小越好，但是必要的监控措施必须要有</p>
<h1 id="平行高交互蜜罐的运行逻辑"><a href="#平行高交互蜜罐的运行逻辑" class="headerlink" title="平行高交互蜜罐的运行逻辑"></a>平行高交互蜜罐的运行逻辑</h1><h2 id="正常模拟"><a href="#正常模拟" class="headerlink" title="正常模拟"></a>正常模拟</h2><p>客户端会正常使用服务端的功能并且产生数据，这些数据会经过黑白名单的判断进到独立的服务端数据存储中，并且客户端本身的基本监控应该运行</p>
<h2 id="攻击者"><a href="#攻击者" class="headerlink" title="攻击者"></a>攻击者</h2><p>攻击者会测试或者与服务端进行交互，交互产生的数据经过黑白名单判断进入用于溯源的资料存储，防守方利用这些资料使用溯源的攻击工具进行溯源。同时客户端如果收集到攻击者的数据可以直接传到用于溯源的资料存储中。</p>
<h1 id="总结"><a href="#总结" class="headerlink" title="总结"></a>总结</h1><p>充钱！对企业来说网络安全就是打游戏，每当企业的网络安全出现问题的时候我就会想起马老板的一句话：“充八万会这样？”</p>
 
      <!-- reward -->
      
    </div>
    

    <!-- copyright -->
    
    <footer class="article-footer">
       
<div class="share-btn">
      <span class="share-sns share-outer">
        <i class="ri-share-forward-line"></i>
        分享
      </span>
      <div class="share-wrap">
        <i class="arrow"></i>
        <div class="share-icons">
          
          <a class="weibo share-sns" href="javascript:;" data-type="weibo">
            <i class="ri-weibo-fill"></i>
          </a>
          <a class="weixin share-sns wxFab" href="javascript:;" data-type="weixin">
            <i class="ri-wechat-fill"></i>
          </a>
          <a class="qq share-sns" href="javascript:;" data-type="qq">
            <i class="ri-qq-fill"></i>
          </a>
          <a class="douban share-sns" href="javascript:;" data-type="douban">
            <i class="ri-douban-line"></i>
          </a>
          <!-- <a class="qzone share-sns" href="javascript:;" data-type="qzone">
            <i class="icon icon-qzone"></i>
          </a> -->
          
          <a class="facebook share-sns" href="javascript:;" data-type="facebook">
            <i class="ri-facebook-circle-fill"></i>
          </a>
          <a class="twitter share-sns" href="javascript:;" data-type="twitter">
            <i class="ri-twitter-fill"></i>
          </a>
          <a class="google share-sns" href="javascript:;" data-type="google">
            <i class="ri-google-fill"></i>
          </a>
        </div>
      </div>
</div>

<div class="wx-share-modal">
    <a class="modal-close" href="javascript:;"><i class="ri-close-circle-line"></i></a>
    <p>扫一扫，分享到微信</p>
    <div class="wx-qrcode">
      <img src="//api.qrserver.com/v1/create-qr-code/?size=150x150&data=https://cutecuteyu.gitee.io/2021/04/08/%E9%AB%98%E4%BA%A4%E4%BA%92%E5%B9%B3%E8%A1%8C%E8%9C%9C%E7%BD%90%E7%9A%84%E5%9F%BA%E7%A1%80%E7%9F%A5%E8%AF%86/" alt="微信分享二维码">
    </div>
</div>

<div id="share-mask"></div>  
    </footer>
  </div>

   
  <nav class="article-nav">
    
      <a href="/2021/04/08/%E6%BA%AF%E6%BA%90%E7%9A%84%E5%9F%BA%E6%9C%AC%E6%80%9D%E8%B7%AF/" class="article-nav-link">
        <strong class="article-nav-caption">上一篇</strong>
        <div class="article-nav-title">
          
            溯源的基本思路
          
        </div>
      </a>
    
    
      <a href="/2021/03/22/%E8%AF%AD%E8%A8%80%E4%BA%A4%E6%B5%81%E4%B8%AD%E7%9A%84%E9%A9%B1%E5%8A%A8%E8%BE%93%E5%85%A5/" class="article-nav-link">
        <strong class="article-nav-caption">下一篇</strong>
        <div class="article-nav-title">语言交流中的驱动输入</div>
      </a>
    
  </nav>

  
   
     
</article>

</section>
      <footer class="footer">
  <div class="outer">
    <ul>
      <li>
        Copyrights &copy;
        2020-2021
        <i class="ri-heart-fill heart_icon"></i> 萌萌哒的小玉玉
      </li>
    </ul>
    <ul>
      <li>
        
        
        
        Powered by <a href="https://hexo.io" target="_blank">Hexo</a>
        <span class="division">|</span>
        Theme - <a href="https://github.com/Shen-Yu/hexo-theme-ayer" target="_blank">Ayer</a>
        
      </li>
    </ul>
    <ul>
      <li>
        
        
        <span>
  <span><i class="ri-user-3-fill"></i>Visitors:<span id="busuanzi_value_site_uv"></span></span>
  <span class="division">|</span>
  <span><i class="ri-eye-fill"></i>Views:<span id="busuanzi_value_page_pv"></span></span>
</span>
        
      </li>
    </ul>
    <ul>
      
    </ul>
    <ul>
      
    </ul>
    <ul>
      <li>
        <!-- cnzz统计 -->
        
        <script type="text/javascript" src='https://s9.cnzz.com/z_stat.php?id=1278069914&amp;web_id=1278069914'></script>
        
      </li>
    </ul>
  </div>
</footer>
      <div class="float_btns">
        <div class="totop" id="totop">
  <i class="ri-arrow-up-line"></i>
</div>

<div class="todark" id="todark">
  <i class="ri-moon-line"></i>
</div>

      </div>
    </main>
    <aside class="sidebar on">
      <button class="navbar-toggle"></button>
<nav class="navbar">
  
  <div class="logo">
    <a href="/"><img src="/images/ayer-side.svg" alt="小玉玉的博客"></a>
  </div>
  
  <ul class="nav nav-main">
    
    <li class="nav-item">
      <a class="nav-item-link" href="/">主页</a>
    </li>
    
    <li class="nav-item">
      <a class="nav-item-link" href="/archives">归档</a>
    </li>
    
  </ul>
</nav>
<nav class="navbar navbar-bottom">
  <ul class="nav">
    <li class="nav-item">
      
      <a class="nav-item-link nav-item-search"  title="Search">
        <i class="ri-search-line"></i>
      </a>
      
      
      <a class="nav-item-link" target="_blank" href="/atom.xml" title="RSS Feed">
        <i class="ri-rss-line"></i>
      </a>
      
    </li>
  </ul>
</nav>
<div class="search-form-wrap">
  <div class="local-search local-search-plugin">
  <input type="search" id="local-search-input" class="local-search-input" placeholder="Search...">
  <div id="local-search-result" class="local-search-result"></div>
</div>
</div>
    </aside>
    <div id="mask"></div>

<!-- #reward -->
<div id="reward">
  <span class="close"><i class="ri-close-line"></i></span>
  <p class="reward-p"><i class="ri-cup-line"></i>请我喝杯咖啡吧~</p>
  <div class="reward-box">
    
    <div class="reward-item">
      <img class="reward-img" src="https://cdn.jsdelivr.net/gh/Shen-Yu/cdn/img/alipay.jpg">
      <span class="reward-type">支付宝</span>
    </div>
    
    
    <div class="reward-item">
      <img class="reward-img" src="https://cdn.jsdelivr.net/gh/Shen-Yu/cdn/img/wechat.jpg">
      <span class="reward-type">微信</span>
    </div>
    
  </div>
</div>
    
<script src="/js/jquery-2.0.3.min.js"></script>
 
<script src="/js/lazyload.min.js"></script>

<!-- Tocbot -->
 
<script src="/js/tocbot.min.js"></script>

<script>
  tocbot.init({
    tocSelector: ".tocbot",
    contentSelector: ".article-entry",
    headingSelector: "h1, h2, h3, h4, h5, h6",
    hasInnerContainers: true,
    scrollSmooth: true,
    scrollContainer: "main",
    positionFixedSelector: ".tocbot",
    positionFixedClass: "is-position-fixed",
    fixedSidebarOffset: "auto",
  });
</script>

<script src="https://cdn.jsdelivr.net/npm/jquery-modal@0.9.2/jquery.modal.min.js"></script>
<link
  rel="stylesheet"
  href="https://cdn.jsdelivr.net/npm/jquery-modal@0.9.2/jquery.modal.min.css"
/>
<script src="https://cdn.jsdelivr.net/npm/justifiedGallery@3.7.0/dist/js/jquery.justifiedGallery.min.js"></script>

<script src="/dist/main.js"></script>

<!-- ImageViewer -->
 <!-- Root element of PhotoSwipe. Must have class pswp. -->
<div class="pswp" tabindex="-1" role="dialog" aria-hidden="true">

    <!-- Background of PhotoSwipe. 
         It's a separate element as animating opacity is faster than rgba(). -->
    <div class="pswp__bg"></div>

    <!-- Slides wrapper with overflow:hidden. -->
    <div class="pswp__scroll-wrap">

        <!-- Container that holds slides. 
            PhotoSwipe keeps only 3 of them in the DOM to save memory.
            Don't modify these 3 pswp__item elements, data is added later on. -->
        <div class="pswp__container">
            <div class="pswp__item"></div>
            <div class="pswp__item"></div>
            <div class="pswp__item"></div>
        </div>

        <!-- Default (PhotoSwipeUI_Default) interface on top of sliding area. Can be changed. -->
        <div class="pswp__ui pswp__ui--hidden">

            <div class="pswp__top-bar">

                <!--  Controls are self-explanatory. Order can be changed. -->

                <div class="pswp__counter"></div>

                <button class="pswp__button pswp__button--close" title="Close (Esc)"></button>

                <button class="pswp__button pswp__button--share" style="display:none" title="Share"></button>

                <button class="pswp__button pswp__button--fs" title="Toggle fullscreen"></button>

                <button class="pswp__button pswp__button--zoom" title="Zoom in/out"></button>

                <!-- Preloader demo http://codepen.io/dimsemenov/pen/yyBWoR -->
                <!-- element will get class pswp__preloader--active when preloader is running -->
                <div class="pswp__preloader">
                    <div class="pswp__preloader__icn">
                        <div class="pswp__preloader__cut">
                            <div class="pswp__preloader__donut"></div>
                        </div>
                    </div>
                </div>
            </div>

            <div class="pswp__share-modal pswp__share-modal--hidden pswp__single-tap">
                <div class="pswp__share-tooltip"></div>
            </div>

            <button class="pswp__button pswp__button--arrow--left" title="Previous (arrow left)">
            </button>

            <button class="pswp__button pswp__button--arrow--right" title="Next (arrow right)">
            </button>

            <div class="pswp__caption">
                <div class="pswp__caption__center"></div>
            </div>

        </div>

    </div>

</div>

<link rel="stylesheet" href="https://cdn.jsdelivr.net/npm/photoswipe@4.1.3/dist/photoswipe.min.css">
<link rel="stylesheet" href="https://cdn.jsdelivr.net/npm/photoswipe@4.1.3/dist/default-skin/default-skin.min.css">
<script src="https://cdn.jsdelivr.net/npm/photoswipe@4.1.3/dist/photoswipe.min.js"></script>
<script src="https://cdn.jsdelivr.net/npm/photoswipe@4.1.3/dist/photoswipe-ui-default.min.js"></script>

<script>
    function viewer_init() {
        let pswpElement = document.querySelectorAll('.pswp')[0];
        let $imgArr = document.querySelectorAll(('.article-entry img:not(.reward-img)'))

        $imgArr.forEach(($em, i) => {
            $em.onclick = () => {
                // slider展开状态
                // todo: 这样不好，后面改成状态
                if (document.querySelector('.left-col.show')) return
                let items = []
                $imgArr.forEach(($em2, i2) => {
                    let img = $em2.getAttribute('data-idx', i2)
                    let src = $em2.getAttribute('data-target') || $em2.getAttribute('src')
                    let title = $em2.getAttribute('alt')
                    // 获得原图尺寸
                    const image = new Image()
                    image.src = src
                    items.push({
                        src: src,
                        w: image.width || $em2.width,
                        h: image.height || $em2.height,
                        title: title
                    })
                })
                var gallery = new PhotoSwipe(pswpElement, PhotoSwipeUI_Default, items, {
                    index: parseInt(i)
                });
                gallery.init()
            }
        })
    }
    viewer_init()
</script> 
<!-- MathJax -->

<!-- Katex -->

<!-- busuanzi  -->
 
<script src="/js/busuanzi-2.3.pure.min.js"></script>
 
<!-- ClickLove -->

<!-- ClickBoom1 -->

<!-- ClickBoom2 -->

<!-- CodeCopy -->
 
<link rel="stylesheet" href="/css/clipboard.css">
 <script src="https://cdn.jsdelivr.net/npm/clipboard@2/dist/clipboard.min.js"></script>
<script>
  function wait(callback, seconds) {
    var timelag = null;
    timelag = window.setTimeout(callback, seconds);
  }
  !function (e, t, a) {
    var initCopyCode = function(){
      var copyHtml = '';
      copyHtml += '<button class="btn-copy" data-clipboard-snippet="">';
      copyHtml += '<i class="ri-file-copy-2-line"></i><span>COPY</span>';
      copyHtml += '</button>';
      $(".highlight .code pre").before(copyHtml);
      $(".article pre code").before(copyHtml);
      var clipboard = new ClipboardJS('.btn-copy', {
        target: function(trigger) {
          return trigger.nextElementSibling;
        }
      });
      clipboard.on('success', function(e) {
        let $btn = $(e.trigger);
        $btn.addClass('copied');
        let $icon = $($btn.find('i'));
        $icon.removeClass('ri-file-copy-2-line');
        $icon.addClass('ri-checkbox-circle-line');
        let $span = $($btn.find('span'));
        $span[0].innerText = 'COPIED';
        
        wait(function () { // 等待两秒钟后恢复
          $icon.removeClass('ri-checkbox-circle-line');
          $icon.addClass('ri-file-copy-2-line');
          $span[0].innerText = 'COPY';
        }, 2000);
      });
      clipboard.on('error', function(e) {
        e.clearSelection();
        let $btn = $(e.trigger);
        $btn.addClass('copy-failed');
        let $icon = $($btn.find('i'));
        $icon.removeClass('ri-file-copy-2-line');
        $icon.addClass('ri-time-line');
        let $span = $($btn.find('span'));
        $span[0].innerText = 'COPY FAILED';
        
        wait(function () { // 等待两秒钟后恢复
          $icon.removeClass('ri-time-line');
          $icon.addClass('ri-file-copy-2-line');
          $span[0].innerText = 'COPY';
        }, 2000);
      });
    }
    initCopyCode();
  }(window, document);
</script>
 
<!-- CanvasBackground -->

<script>
  if (window.mermaid) {
    mermaid.initialize({ theme: "forest" });
  }
</script>


    
  </div>
</body>

</html>